PT-2024-22787 · Collabora · Collabora Online

David Miller

·

Published

2024-04-04

·

Updated

2025-09-23

·

CVE-2024-29182

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Collabora Online versions prior to 23.05.10.1
Description A stored cross-site scripting issue was found in Collabora Online, a collaborative online office suite based on LibreOffice. An attacker could create a document with an XSS payload in document text referenced by a field, which, if hovered over to produce a tooltip, could be executed by the user's browser.
Recommendations For versions prior to 23.05.10.1, upgrade to Collabora Online 23.05.10.1 or higher to resolve the issue. As a temporary workaround, consider restricting the use of tooltips in documents to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-29182
GHSA-9GMW-5Q2C-4398

Affected Products

Collabora Online